VPN overview for Apple device deployment (2024)

VPN overview for Apple device deployment (1)

Secure access to private corporate networks is available in iOS, iPadOS, macOS, tvOS, watchOS, and visionOS using established industry-standard virtual private network (VPN) protocols.

Supported protocols

iOS, iPadOS, macOS, tvOS, watchOS, and visionOS support the following protocols and authentication methods:

iOS, iPadOS, macOS, and visionOS also support the following protocols and authentication methods:

  • L2TP over IPsec: User authentication by MS-CHAP v2 password, two-factor token, certificate, machine authentication by shared secret or certificate

    macOS can also use Kerberos machine authentication by shared secret or certificate with L2TP over IPsec.

  • IPsec: User authentication by password, two-factor token, and machine authentication by shared secret and certificates

If your organization supports those protocols, no additional network configuration or third-party apps are required in order to connect Apple devices to your virtual private network.

Support includes technologies such as IPv6, proxy servers, and split tunneling. Split tunneling provides a flexible VPN experience when connecting to an organization’s networks.

In addition, the Network Extension framework allows third-party developers to create a custom VPN solution for iOS, iPadOS, macOS, tvOS, and visionOS. Several VPN providers have created apps to help configure Apple devices for use with their solutions. To configure a device for a specific solution, install the provider’s companion app and optionally, provide a configuration profile with the necessary settings.

VPN On Demand

In iOS, iPadOS, macOS, and tvOS, VPN On Demand lets Apple devices automatically establish a connection on an as-needed basis. It requires an authentication method that doesn’t involve user interaction—for example, certificate-based authentication. VPN On Demand is configured using the OnDemandRules key in a VPN payload of a configuration profile. Rules are applied in two stages:

  • Network detection stage: Defines VPN requirements that are applied when the device’s primary network connection changes.

  • Connection evaluation stage: Defines VPN requirements for connection requests to domain names on an as-needed basis.

Rules can be used to do things like:

  • Recognize when an Apple device is connected to an internal network and VPN isn’t necessary

  • Recognize when an unknown Wi-Fi network is being used and require VPN

  • Start the VPN when a DNS request for a specified domain name fails

Per App VPN

In iOS, iPadOS, macOS, watchOS, and visionOS 1.1, VPN connections can be established on a per-app basis, which provides more granular control over which data goes through VPN. This ability to segregate traffic at the app level allows the separation of personal data from organizational data—resulting in secure networking for internal-use apps, while at the same time preserving the privacy of personal device activity.

Per App VPN lets each app that’s managed by a mobile device management (MDM) solution communicate with the private network using a secure tunnel, while excluding unmanaged apps from using the private network. Managed Apps can be configured with different VPN connections to further safeguard data. For example, a sales quote app might use an entirely different data center than an accounts payable app.

After creating a Per App VPN for any VPN configuration, you need to associate that connection with the apps using it to secure the network traffic for those apps. You do this with the Per App VPN mapping payload (macOS) or by specifying the VPN configuration within the app installation command (iOS, iPadOS, macOS, visionOS 1.1).

Per App VPN can be configured to work with the built-in IKEv2 VPN client in iOS, iPadOS, watchOS, and visionOS 1.1. For information about Per App VPN support in custom VPN solutions, contact your VPN vendors.

Note: To use Per App VPN in iOS, iPadOS, watchOS 10, and visionOS 1.1, an app must be managed by MDM.

Always On VPN

Always On VPN available for IKEv2 gives your organization full control over iOS and iPadOS traffic by tunneling all IP traffic back to the organization. Your organization can now monitor and filter traffic to and from devices, secure data within your network, and restrict device access to the internet.

Always On VPN activation requires device supervision. After the Always On VPN profile is installed on a device, Always On VPN automatically activates with no user interaction, and it stays activated (including across restarts) until the Always On VPN profile is uninstalled.

With Always On VPN activated on the device, the VPN tunnel bring-up and teardown is tied to the interface IP state. When the interface gains IP network reachability, it attempts to establish a tunnel. When the interface IP state goes down, the tunnel is torn down.

Always On VPN also supports per-interface tunnels. For devices with cellular connections, there’s one tunnel for each active IP interface (one tunnel for the cellular interface and one tunnel for the Wi-Fi interface). As long as the VPN tunnels are up, all IP traffic is tunneled. Traffic includes all IP-routed traffic and all IP-scoped traffic (traffic from first-party apps such as FaceTime and Messages). If the tunnels aren’t up, all IP traffic is dropped.

All traffic tunneled from a device reaches a VPN server. You can apply optional filtering and monitoring treatments before forwarding the traffic to its destination within your organization’s network or to the internet. Similarly, traffic to the device is routed to your organization’s VPN server, where filtering and monitoring processes may be applied before being forwarded to the device.

Note: Apple Watch pairing isn’t supported with Always On VPN.

Transparent proxy

Transparent proxies are a special VPN type on macOS and can be used in different ways to monitor and transform network traffic. Common use cases are content filter solutions and brokers to access cloud services. Due to the variety of uses, it’s a good idea to define the order in which those proxies get to see and handle traffic. For example, you want to invoke proxy filtering network traffic before invoking a proxy that encrypts the traffic. You do this by defining the order in the VPN payload.

See alsoUse a VPN proxy and certificate configuration in Apple devicesVPN settings overview for Apple devices

VPN overview for Apple device deployment (2024)

FAQs

Do Apple devices have a built in VPN? ›

The iPhone doesn't have a built-in VPN but has VPN settings if you wish to build or install one. To make a VPN work, you would need to complete a manual setup and find a server to connect to, which is not an option for most users.

Does Apple recommend using a VPN? ›

Apple devices have the option of configuring a VPN directly on them. No app is necessary. Apple does not recommend the use of any third party security apps. Apple's operating systems have all the security they need built in.

What is the Apple VPN setting? ›

A “VPN on an iPhone” means a virtual private network you use on your iPhone to securely connect to the internet. A VPN service routes your traffic via remote VPN servers, hiding your IP address, so neither your internet provider nor other third parties can snoop on your online activity.

What is VPN and device management in iPhone? ›

What does VPN do on iPhone? The main function of a VPN setting on an iPhone is to secure data sent to and from the device and ensure all web activity remains private. However, a VPN service can also be useful for circumventing geographical restrictions, accessing location-specific content,.

Does Apple have a free VPN? ›

You can use Free VPN with your Apple ID on other iPhone, iPad and iPod devices. You can also register a unlimited number of devices. Free VPN, blocks 98% of ads, providing a better and seamless experience.

Does iPad have built-in VPN? ›

Does the Apple iPad have a built-in VPN? Your iPad can be configured with a VPN but does not come with any preinstalled VPN applications. You can set your iPad up to send and receive data through a server using IKEv2 and L2TP/IPSec protocols, but Apple does not provide VPN servers.

What is the most secure VPN for Apple? ›

ExpressVPN is the best iPhone VPN I've tested, thanks to its excellent privacy, great content unblocking power, and streamlined apps that put the competition to shame. Tons of servers, reliable connections on both Wi-Fi and mobile data, plus excellent customer support make ExpressVPN perfect for iOS.

Why does VPN not work on iPhone? ›

Sometimes, a VPN profile may become corrupted or misconfigured, causing connectivity issues. Turn off your VPN app. Go to iPhone Settings and navigate to the General tab, then scroll down and tap on VPN & Device Management and remove all VPN profiles. Relaunch the VPN app and allow it to configure a new profile.

Does VPN affect Apple location? ›

A VPN hides your iPhone's IP address and gives you a new one from one of its servers. Essentially, changing your IP address alters your phone's virtual location, so ISPs (internet service providers), Netflix, websites, and apps won't know where you really are.

Do iPhones come with VPN already installed? ›

Keep in mind that iPhones don't have built-in VPNs. This means you can't connect to a VPN with only the available iPhone settings.

How do I enable Apple VPN? ›

Use the VPN on your iPhone
  1. Go to the “Settings” app on your phone.
  2. Go to “General.”
  3. Choose “VPN.”
  4. Tap the status switch on your VPN to turn it on.

How do I know if my iPhone has a VPN? ›

Additionally, you can check the VPN settings on the iPhone by going to the "Settings" app and selecting "General" > "VPN." If there are VPN configurations set up on the device, it is a strong indicator that the user is using a VPN.

How do I setup VPN and Device Management on my iPhone? ›

To add a VPN configuration on your iPhone, start with these steps: Tap Settings > General > VPN & Device Management. Tap Add Configuration.

What is the best free VPN for iOS? ›

Best free VPNs for iPhone in 2024
  • PrivadoVPN Free: the best free iPhone VPN overall.
  • Proton VPN Free: the best for security.
  • Windscribe Free: free iPhone VPN with most servers.
  • Hotspot Shield Basic: free iPhone VPN with unlimited data.
  • Atlas VPN Free: the best free VPN for Mac users.
Mar 21, 2024

Where is Device Management on iPhone? ›

On a user-owned iPhone or iPad, open Settings > General > VPN & Device Management to show the managed account for the MDM profile. Then, access the MDM enrollment profile and more details by tapping Managed Account > Profiles and Device Management.

How do I turn on my Apple built in VPN? ›

Use the VPN on your iPhone
  1. Go to the “Settings” app on your phone.
  2. Go to “General.”
  3. Choose “VPN.”
  4. Tap the status switch on your VPN to turn it on.

Does Safari have a VPN? ›

No, Safari on iPhone does not have a built-in VPN. However, you can use a third-party VPN app, like ExpressVPN, to protect your privacy and security when browsing the web on your iPhone. It's worth noting that Apple does offer a privacy feature called iCloud Private Relay, which is available on iOS 15 and iPadOS 15.

How do I get a free VPN on my iPhone? ›

Best free VPNs for iPhone in 2024
  1. PrivadoVPN Free. The best free iPhone VPN. ...
  2. Proton VPN Free. Unlimited data allowance and top-notch digital privacy. ...
  3. Windscribe Free. Powerful and secure with generous streaming support. ...
  4. Hotspot Shield Basic VPN. Absolutely no data limits, but look out for the ads. ...
  5. Atlas VPN Free.
Mar 21, 2024

Top Articles
Latest Posts
Article information

Author: Rueben Jacobs

Last Updated:

Views: 5673

Rating: 4.7 / 5 (57 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Rueben Jacobs

Birthday: 1999-03-14

Address: 951 Caterina Walk, Schambergerside, CA 67667-0896

Phone: +6881806848632

Job: Internal Education Planner

Hobby: Candle making, Cabaret, Poi, Gambling, Rock climbing, Wood carving, Computer programming

Introduction: My name is Rueben Jacobs, I am a cooperative, beautiful, kind, comfortable, glamorous, open, magnificent person who loves writing and wants to share my knowledge and understanding with you.